THEA TECH SOLUTIONS · BANGKOK, THAILAND
AI software audits.
A clear path to hardening.
A €3,500 five-day senior review of your AI-built application. Get prioritised security, data and reliability findings, plus a practical fix roadmap before your next launch or customer review.
Production-hardened for fintech, healthtech, and regulated EU startups
What I look for
What I actually look for
Examples of risks the review checks for, not findings from your application or a promise that an issue will be found.
Secrets in the client bundle
Check whether secrets appear in client assets, repository history or logs, and whether exposed keys need rotation.
PII in your logs
Personal data in logs can create privacy and security risks. Where GDPR applies, certain infringements can attract fines up to €20M or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual sanction depends on the case.
European Commission: GDPR sanctionsOpen row-level security
Test whether one tenant can reach another tenant's records through the relevant read and write paths.
No idempotency on webhooks
Check whether retries can repeat payments or other irreversible actions, and how the system recovers.
Single-source data dependency
Review critical vendor dependencies and what happens if data or service becomes unavailable.
No audit trail
Missing records can make it harder to investigate incidents or demonstrate how a decision was made.
EU AI Act
Understand your product's obligations
The EU AI Act takes a risk-based approach. Obligations depend on the system, its intended use and your role. AI-assisted development alone does not establish that your application falls within a particular category.
Identify the use case
Document where AI operates, who uses the outputs and which decisions it affects.
Review technical controls
Check relevant disclosure, oversight and record-keeping requirements with appropriate specialist advice.
Confirm applicability
The audit flags technical questions and evidence gaps. It does not provide legal advice or certification.
Proof
What this looks like in practice
A founder told me he rebuilt my AML screening system in a weekend with Claude Code.
He found OpenSanctions — 400+ sources, free download. Wired it up in three days. Looked finished.
What he missed:
That data is free for non-commercial use only. Screening your own customers is commercial. He needs a license he doesn't have.
Search "Gazprom" — 44 results. Search "Газпром" — 327 results. Same company, different alphabet. His system catches one of them.
The system he replaced pulls 13 government sanctions feeds direct from source. OFAC, UN, EU, UK, Australia, Canada, UAE, Singapore, Japan, Switzerland, New Zealand, Hong Kong, Interpol. Each with its own collection worker. Because if you depend on one aggregator and it changes terms, your screening goes blind.
He didn't build an AML system. He built the demo of one.
The demo is now free. The difference between the demo and the thing that survives an audit is the entire job.
Pricing
Pricing
Start with the fixed-price audit. Follow-on hardening and ongoing engineering are optional, separately scoped engagements.
Production Readiness Audit
€3,500 · 5 days · fixed price
A prioritised findings report with evidence, trigger conditions, impact and estimated fix effort. Includes a 90-day roadmap and handover. Implementation and retesting are separate.
View paid audit scope →Hardening Sprint
€6,000 – €10,000 · 4 weeks
Fix the top findings from the audit. RLS policies, webhook idempotency, secrets rotation, audit trails, monitoring. Scope the fixes and acceptance checks separately, including post-fix retesting.
Retained
€1,500 – €4,000/mo
Ongoing data layer, monitoring, evals, sign-off, on-call. For products that passed the audit and need someone accountable when it breaks at 2am.
Client words
What they say.
"He integrated AI-driven AML screening into our compliance pipeline across 1.7 million sanctions records. It actually works in production, not just a demo."
Kenneth
Founder, HubSecure
"Riz understood the compliance constraints from day one. In regulated fintech, that kind of reliability is rare in an external partner."
Venu
Director, Qwil
"236 tasks, 600 tests, three apps — one person. Riz delivered a complete product, not just code."
Geir-Ove
Founder, AsyncQuiz
"We needed senior-level execution without the ramp-up time. Riz shipped production features faster than most full-time hires I've seen."
Sahil Gupta
Founder & CEO, Noah
"Page loads went from seconds to milliseconds. Riz delivered faster than our timeline and the quality exceeded what we expected."
Akta Adani
Co-Founder & CEO, Nomadory
Selected work
AI & full-stack projects we've shipped.
mymuaythai.app
Joe's vision. Our engineering. Built from inside the sport's home country.
mymuaythai.app is a platform connecting Muay Thai gyms, trainers, and students across Thailand. Joe had the vision, the…
View case study →AsyncQuiz
Async quiz competition platform for a Norwegian client. Complex, multilingual, on deadline.
SparSammenAS is a Norwegian company building a quiz competition platform where teams compete asynchronously — no shared…
View case study →Nomadory Shop
Headless Shopify + Next.js 15 for a B2B nomad gear brand. Fast, flexible, no bloat.
Nomadory is a B2B nomad gear brand. They needed a storefront that didn't feel like a Shopify theme — custom design,…
View case study →SimplySmartChat
AI-powered WooCommerce sales assistant. RAG pipeline meets real product knowledge.
An AI chatbot that actually knows the product catalog. Built for a WooCommerce store — the bot ingests product…
View case study →Thea Tech Internal Automation
n8n workflows, AI agents, and infrastructure automation. The backbone behind the business.
The internal systems that keep Thea Tech running efficiently. n8n queue-mode deployment on a Contabo VPS handling…
View case study →HubSecure
Multi-tenant FinTech compliance platform. KYC, AML, blockchain, AI agents — 12+ repos.
HubSecure is a multi-tenant FinTech compliance platform for KYC/AML verification, built for BCV Group. The system…
View case study →FAQ
Questions founders ask.
What is a Production Readiness Audit?
A €3,500 five-day engineering review of one AI-built application, with repositories and critical flows agreed in writing. You receive prioritised findings, coverage limits, a 90-day fix roadmap and a handover. The review begins once scope and access are ready.
Is the scoping call the audit?
No. The free 30-minute call covers fit, scope, access and timing. It does not include a code review or findings report. The paid audit starts after the written scope and commercial terms are accepted.
Does using AI to write code make my product an AI system?
The development tool alone does not determine your obligations. EU AI Act applicability depends on the system, its use and your role. The audit can flag technical questions for specialist advice; it is not legal advice or compliance certification.
What happens after the audit?
Your team can implement the roadmap, or ask for a separate hardening proposal. We agree the fixes, acceptance checks and retesting before that work starts. No retainer is required to buy the audit.
Will the audit find every issue?
No bounded review can guarantee this. The report records what was reviewed, observed issues and any access or coverage limits so you can decide what to do next.
Get started
Shipped something with AI? Get it audited before it meets real users.
Production Readiness Audit. €3,500. Five days. Prioritised findings and a practical fix roadmap. Implementation and retesting are separate.
Production Readiness Audit →